<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:photoview:photoview:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aphotoviewphotoview/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 23 Sep 2026 06:41:22 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aphotoviewphotoview/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass Vulnerability in Photoview shareAlbum Mutation</title><link>https://feed.craftedsignal.io/briefs/2026-09-photoview-auth-bypass/</link><pubDate>Wed, 23 Sep 2026 06:41:22 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-photoview-auth-bypass/</guid><description>Photoview versions through 2.4.0 contain an authorization bypass in the shareAlbum GraphQL mutation, allowing authenticated users to generate unauthorized share tokens for albums owned by others.</description><content:encoded><![CDATA[<p>Photoview versions 2.4.0 and earlier are affected by an authorization bypass vulnerability located in the shareAlbum GraphQL mutation. The vulnerability permits an authenticated user to perform a GraphQL request specifying an arbitrary album ID, even if that album does not belong to the requesting user. The application fails to validate ownership of the target album before processing the request, resulting in the generation of a functional share token. An attacker can leverage this to create persistent public access links for private albums, exposing sensitive photo collections and nested sub-albums to unauthorized parties without the owner's knowledge. This issue poses a significant risk to data privacy for users deploying Photoview in multi-user or shared environments.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the complete unauthorized exposure of private media collections. Because the generated share tokens provide persistent access, an attacker retains control over the shared link, potentially leading to widespread data exfiltration if the albums contain sensitive personal content. The vulnerability affects all users running vulnerable instances of Photoview, impacting personal or organizational storage instances.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade to the latest version of Photoview beyond 2.4.0 to resolve the authorization logic flaw.</li>
<li>Audit current album share settings within the application to identify and revoke any suspicious or unauthorized tokens.</li>
<li>Restrict access to the GraphQL endpoint for unauthorized users if immediate patching is not possible.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>web-application</category><category>graphql</category></item></channel></rss>